Skip to main content

Overview

Run these scripts on end-user devices through your MDM (Mobile Device Management) platform. They configure each AI coding tool to route through the Unbound Gateway.
All scripts must be run as root (or with administrator privileges) — each one checks first and exits if it is not. On macOS and Linux it exits with This script requires administrator/root privileges; on Windows it asks for an elevated shell instead, so grep the run’s output for either.The commands below are written with sudo so they work when you run them by hand. Your MDM provider already executes in a root context, so drop the sudo prefix when you paste them into a deployment profile.
Before deploying, ensure your MDM provider is connected or devices are imported and you have an admin API key from gateway.getunbound.ai/configure.
Replace these placeholders in every command below:
  • YOUR_ADMIN_API_KEY — an admin API key, taken from the install command on Configure
  • https://backend.getunbound.ai — if your organization uses a custom backend URL, replace this with your own

Cursor

Configure Cursor:

Claude Code

Configures the hooks for governance and analytics, and leaves the device’s existing Anthropic authentication as it is:

Codex

Configures the hooks for governance and analytics, and leaves the device’s existing ChatGPT sign-in as it is:
It does clear any export OPENAI_API_KEY= line from each user’s shell profile (the machine-wide value on Windows) and any openai_base_url from ~/.codex/config.toml. A developer who authenticated Codex with their own API key that way has to set it again.

GitHub Copilot

Hooks-based — works with both the VS Code extension and the copilot CLI on the user’s existing Copilot subscription:

Augment Code

Hooks-based — works with both the Augment VS Code extension and the Auggie CLI:

Remove Unbound Configuration

To remove the Unbound Gateway configuration from a device, run that tool’s mdm-install command with only the --clear flag. Clearing does not require an API key or backend URL. This removes all Unbound-related settings for that tool and restores it to its default state. For example, to clear Cursor:
Each user’s own ~/.unbound/config.json is left in place, so a developer who set Unbound up themselves is not logged out by a fleet rollback. Delete that file, or run unbound nuke as that user, to remove it too.

Keep enforcement in place

Deploying through MDM writes Claude Code, Cursor and Augment Code into system-wide managed settings; Codex and the Copilot CLI are configured in each developer’s own profile. How well each of those is protected from the user depends on the platform — on Windows, Cursor’s and Augment Code’s files are not locked down by the installer. Schedule the deployment to run daily so every tool stays configured, and read Tamper Resistance for the per-tool, per-platform detail.

Tamper Resistance

Best practices for keeping Unbound active on every device with managed settings.